Suspicious
Suspect

PE Executable
MD5: fe0d7a6aab8f8b99b6ade0e2a31e1796
Size: 876.54 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 fe0d7a6aab8f8b99b6ade0e2a31e1796
Sha1 5547844fa8a3a8693172e39a86d0ab60cd1a5654
Sha256 09336f9e01cf88ff44bf3c9a1b54e6d69f6b4e3a390bc42e8cbe0510ee23b72c
Sha384 c3347a5d0d8fb3290b9497a9609027d8e35bdb901d00fe1f1cd2b0945d31a8ebd22c2441313986bc7bbea51d86067abd
Sha512 9a771634e4cd2c7731e14a2087ed2ce690f8aa7a186c413c9a5320c06bb0647fb0527ab441820f57b36af8121f8c3094db60a5b9ede9bf786db5374a4c94ab76
SSDeep 24576:EIY/Fzp2fJdtCPR68Csb0k+0EMVC3fjqz7X:EICzkfJdtqzlIkGWYwj
TLSH BB1533035DDB1463D9D588B5886B467BF5E9568300C6068F98CDE086FA2F61BAC7FB30
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
uzfzgznawgdxe.Resources
start.bat
starter.bat
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
XBinderOutput.exe
Full Name
XBinderOutput.exe
EntryPoint
System.Void Program::Main()
Scope Name
XBinderOutput.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
XBinderOutput
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
10
Main Method
System.Void Program::Main()
Main IL Instruction Count
10
Main IL
ldc.i4 2000
call System.Void System.Threading.Thread::Sleep(System.Int32)
call System.Boolean Program::CreateMutex()
brtrue.s IL_001B: ldnull
call System.Int32 System.Environment::get_ExitCode()
call System.Void System.Environment::Exit(System.Int32)
ldnull <null>
call System.Object Program::WorkF(System.Object)
pop <null>
ret <null>
Module Name
XBinderOutput.exe
Full Name
XBinderOutput.exe
EntryPoint
System.Void Program::Main()
Scope Name
XBinderOutput.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
XBinderOutput
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
10
Main Method
System.Void Program::Main()
Main IL Instruction Count
10
Main IL
ldc.i4 2000
call System.Void System.Threading.Thread::Sleep(System.Int32)
call System.Boolean Program::CreateMutex()
brtrue.s IL_001B: ldnull
call System.Int32 System.Environment::get_ExitCode()
call System.Void System.Environment::Exit(System.Int32)
ldnull <null>
call System.Object Program::WorkF(System.Object)
pop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
uzfzgznawgdxe.Resources
start.bat
starter.bat
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙